DLP and mail flow rules: the rule model, the engine and the node cache
Phase 2e of the DLP and mail flow rules spec, in the features crate. - rules.rs: a rule (§2.2) with its conditions (§2.3) and actions (§2.4), as JSON under R/r in the fork's subspace. validate() enforces the spec's shape: DLP rules check outgoing mail and have exactly one of block, warn or hold; transport rules have neither those nor detectors; lists, header names, header values (one line), addresses, texts, word lists, patterns and detector ids are checked. - engine.rs: rules compiled once (word lists to automata, patterns to size-limited regexes) and run in priority order with exceptions and stop processing. Each detector runs at most once per message and only when a rule asks for it. The outcome lists what matched with each detector's count, and decides DLP strictest first: block, hold, warn; an override answers warnings only (§2.5). - cache.rs: each node's compiled copy, refreshed after 30 seconds or at once when this node changes a rule. Nothing calls this yet: the JMAP object and the check at DATA follow. 55 unit tests in mailflow.
This commit is contained in:
@@ -6,18 +6,24 @@
|
||||
|
||||
//! Data loss prevention and mail flow rules (dlp-and-mail-flow-rules spec).
|
||||
//!
|
||||
//! Pure functions over text and attachment bytes, so everything here is
|
||||
//! unit-tested without a server:
|
||||
//! Mostly pure functions over text and attachment bytes, unit-tested
|
||||
//! without a server:
|
||||
//!
|
||||
//! - [`detectors`]: find identifiers in text (payment cards, IBANs,
|
||||
//! national ID numbers, keys), each by its published format and check
|
||||
//! (§2.3);
|
||||
//! - [`words`]: an organization's own word lists and patterns;
|
||||
//! - [`extract`]: the text of an attachment, or why it can't be read.
|
||||
//! - [`extract`]: the text of an attachment, or why it can't be read;
|
||||
//! - [`rules`]: what a rule is, its checks, and where rules are kept;
|
||||
//! - [`engine`]: rules compiled and run against a message;
|
||||
//! - [`cache`]: each node's compiled copy.
|
||||
//!
|
||||
//! Nothing here writes what it finds anywhere: callers get counts, and the
|
||||
//! matched text never leaves the evaluation (§2.7).
|
||||
|
||||
pub mod cache;
|
||||
pub mod detectors;
|
||||
pub mod engine;
|
||||
pub mod extract;
|
||||
pub mod rules;
|
||||
pub mod words;
|
||||
|
||||
Reference in New Issue
Block a user